A new OCC bulletin underscores the need for banks to conduct appropriate security risk assessment and mitigation on all applications, regardless of whether developed internally, by a vendor or by outside developers. The agency says the FFIEC’s information technology examination handbooks on information security, development and acquisition give banks basic guidance about application security. The bulletin also lists in two appendices the 10 most common vulnerabilities in web-based applications and considerations for request for information and request for proposal when banks purchase application software or services.”]
Source: https://www.bankinfosecurity.com/occ-to-banks-dont-forget-application-security-a-861

